๐ JWT Generator
Algorithm: HS256 (HMAC-SHA256), fixed
Enter a secret key
Enter a JSON payload and a secret key to generate an HS256 (HMAC-SHA256) signed JWT (JSON Web Token) on the spot. The signature is computed using the browser's built-in Web Crypto API.
How to use
- Edit the payload JSON (set any claims you want, like sub, name, iat).
- Enter the secret key to sign with.
- The generated JWT appears automatically โ click "Copy" to copy it to your clipboard.
How the calculation works
A JWT (JSON Web Token, RFC 7519) carries signed claims such as login information. It is three parts โ header.payload.signature โ joined by dots. This tool signs a JWT with HS256 from the payload JSON and secret you enter. 1. Base64URL-encode the header {"alg":"HS256","typ":"JWT"} 2. Serialise the payload JSON without whitespace and Base64URL-encode it 3. Sign "header.payload" with HMAC-SHA256 using the secret, and Base64URL-encode the signature 4. Join the three parts with dots The signature is computed with the browser's Web Crypto API. A receiver recomputes it with the same secret; if it matches, the token has not been tampered with.
Worked example
Payload: {"sub":"1234567890","name":"John Doe","iat":1516239022} Secret: your-256-bit-secret Result (identical to the jwt.io sample) eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Things to be aware of
- A JWT payload is not encrypted; anyone can Base64URL-decode and read it. Never put passwords or other secrets in it.
- Use a long random secret for HS256 (32 bytes or more). Short secrets can be brute-forced.
- An expiry claim (exp) limits the damage if a token leaks. Never enter production secrets into a web tool like this.
FAQ
Where is the signature computed?
Entirely in your browser, using the built-in Web Crypto API (crypto.subtle) to compute the HMAC-SHA256 signature. Your secret key is never sent to a server.
Does this support algorithms other than HS256?
No, the current version only supports HS256 (HMAC-SHA256).
Can I verify the generated JWT is correct?
Yes โ paste it into this site's JWT Decoder to check its contents, or verify the signature with an external tool like jwt.io using the same secret key.